Unknown · Netbox Device Type Library · CVE-2026-54916
**Name of the Vulnerable Software and Affected Versions**
NetBox Device Type Library (affected versions not specified)
**Description**
An issue exists where the absence of `tests/init.py` and the lack of `--import-mode=importlib` cause pytest to place the tests directory at the front of `sys.path` during collection. This allows an unauthenticated contributor to perform module shadowing by adding a module, such as `tests/git.py`, which shadows GitPython when `tests/definitions test.py` executes `from git import Git, Repo`, or by adding `tests/conftest.py` for automatic execution. Consequently, Python imports and runs the malicious module before any test function, enabling arbitrary code execution on the GitHub Actions runner, tampering with test results, and unauthorized access to tokens or network resources exposed to the workflow.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.